Application Security Engineer

Strategy

Tysons (VA)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Strategy in Tysons Corner, VA is seeking an Application Security Engineer to secure AI coding within engineering processes. This role integrates security measures throughout the SDLC, focusing on vulnerability management and governance.

Ideal candidates will hold a Bachelor's in Computer Science and have experience in software security with AI tools. Strategy offers a collaborative environment that values innovation and personal contributions.

Qualifications

  • Minimum 2 years of software development or software security experience in an agile environment.
  • Hands-on experience applying Generative AI and/or ML to security use cases.
  • Fluent in one or more programming languages, such as Python, Java, JavaScript.

Responsibilities

  • Evaluate and establish guardrails for secure use of AI coding assistants within the engineering organization.
  • Work closely with development teams to integrate security into the SDLC.
  • Conduct manual and automated penetration testing of applications.

Skills

Generative AI
Secure coding principles
Collaboration skills
Vulnerability management
Effective communication

Education

Bachelor's degree in Computer Science, Engineering, or related field

Tools

SAST Tools
DAST Tools
IAST Tools
SCA Tools

Job description

Company Description

Strategy (Nasdaq: MSTR) is at the forefront of transforming organizations into intelligent enterprises through data-driven innovation. We don't just follow trends—we set them and drive change. As a market leader in enterprise analytics and AI software, we've pioneered the BI and analytics space, empowering people to make better decisions and revolutionizing how businesses operate. We are now also at the forefront of AI disruption, providing data via our enterprise semantic layer to AI agents, tools, and platforms.

But that's not all. Strategy is also leading a groundbreaking shift in digital assets, adopting bitcoin as our primary treasury reserve asset in 2020. Since then, we have issued innovative bitcoin-backed securities and have been the leader in bitcoin treasury companies. This visionary move has helped us build a fortress balance sheet and is solidifying our position as a forward-thinking, innovative force in the market.

Our people are the core of our success. At Strategy, you'll join a team of smart, creative minds working on dynamic projects with cutting-edge technologies. We thrive on curiosity, innovation, and a relentless pursuit of excellence.

Our corporate values—bold, agile, engaged, impactful, and united—are the foundation of our culture. As we lead the charge into the new era of AI and financial innovation, we foster an environment where every employee's contributions are recognized and valued.

Join us and be part of an organization that lives and breathes innovation every day. At Strategy, you're not just another employee, you're a crucial part of a mission to push the boundaries of analytics and redefine financial investment.

Application Security Engineer

Tysons Corner, VA – Full‑time, in person, 5 days per week at the Strategy Office.

Responsibilities
  • AI Security Governance: Evaluate and establish guardrails for the secure use of AI coding assistants (e.g., Copilot, Cursor, Claude) within the engineering organization, including policy development around AI‑generated code review, training data exposure risks, and prompt injection vulnerabilities in AI‑integrated applications.
  • Secure SDLC Integration: Work closely with development teams to integrate security into the SDLC, including threat modeling, secure code reviews, and security testing.
  • Vulnerability Management: Identify, triage, and remediate security vulnerabilities through static and dynamic application security testing (SAST/DAST) and software composition analysis (SCA) tools.
  • Security Assessments & Penetration Testing: Conduct manual and automated penetration testing of web, mobile, and cloud applications to detect security flaws.
  • Secure Code Review: Analyze source code using both manual review and AI‑assisted code analysis tools (e.g., GitHub Copilot Autofix, Semgrep, or similar) to surface vulnerabilities earlier in the development cycle and deliver actionable, in‑context remediation guidance to developers.
  • Threat Modeling & Risk Analysis: Perform threat modeling to anticipate potential attack vectors and improve security architecture.
  • DevSecOps Enablement: Support and enhance DevSecOps initiatives by integrating AI‑assisted security automation within CI/CD pipelines, including AI‑powered SAST/DAST tools and LLM‑based code scanning to accelerate vulnerability detection at the point of commit.
  • Incident Response & Remediation: Assist in investigating security incidents related to applications and work with engineering teams to remediate threats.
  • Security Awareness & Training: Educate and mentor developers on OWASP Top 10, SANS 25, and other security best practices.
Qualifications
  • Bachelor's degree in Computer Science, Engineering, or related field.
  • Minimum 2 years of software development or software security experience in an agile environment.
  • Hands‑on experience applying Generative AI and/or ML to security use cases—such as vulnerability triage, threat detection, or secure code review automation—and a strong drive to stay current as AI security tooling evolves.
  • Hands‑on experience with SAST, DAST, IAST, and SCA tools (e.g., Checkmarx, Fortify, Veracode, SonarQube, Burp Suite, ZAP).
  • Fluent in one or more programming languages, such as Python, Java, JavaScript.
  • Strong knowledge of secure coding principles and application security frameworks.
  • Familiarity with security tools (e.g., static and dynamic analysis tools, vulnerability scanners).
  • Understanding of security standards and regulations (e.g., OWASP, NIST).
  • Experience with cloud security best practices in AWS, Azure, or GCP.
  • Familiarity with AI/LLM‑specific security risks including prompt injection, model poisoning, insecure output handling, and the OWASP Top 10 for LLM Applications.
  • Strong work ethic with a commitment to meeting business needs and effectively collaborating with global colleagues.
  • Effective interpersonal skills; ability to collaborate successfully with both technical and non‑technical stakeholders.
  • Ability to articulate complex technical concepts with clarity, supported by effective written and verbal communication skills.

Strategy is an equal opportunity employer. All applicants will receive consideration for employment without regard to race, creed, color, religion, national origin, gender, sex, sexual orientation, gender identity, disability, veteran status, age, genetic information, or any other legally protected basis. Strategy provides reasonable accommodation for qualified individuals with disabilities in the hiring process. For assistance, contact application_accommodations@strategy.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff AI Engineer
Staff AI Engineer

SecurityScorecard • Austin (TX)

Hybrid
USD 170,000 - 215,000
Health benefits
Unlimited PTO
Tuition reimbursement
+2
Director, Application Security Austin, TX
Director, Application Security Austin, TX

Webai • Austin (TX)

On-site
USD 180,000 - 280,000
Competitive salary
Health benefits (medical/dental/vision
401(k) match
+7
Director, Application Security
Director, Application Security

ProducePay • Austin (TX)

On-site
USD 180,000 - 230,000
Competitive salary
Health, dental, and vision benefits
401(k) match (U.S.-based)
+5
AI Security Engineer
AI Security Engineer

tms • Chicago (IL)

Hybrid
USD 110,000 - 140,000
Generous medical, dental, vision benefits
401(k) with company match
Tuition reimbursement
+2
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Staff AI Engineer
Staff AI Engineer

Zoomcar • New York (NY)

On-site
USD 200,000 - 240,000
Health benefits
Unlimited PTO
Stock options
Senior AI Engineer
Senior AI Engineer

Zoomcar • United States

On-site
USD 160,000 - 185,000
Competitive salary
Stock options
Health benefits
+3
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Senior AI Engineer
Senior AI Engineer

Zoomcar • New York (NY)

On-site
USD 170,000 - 205,000
Competitive salary
Stock options
Unlimited PTO
+2
Senior AI Engineer
Senior AI Engineer

AlleyCorp • Austin (TX)

On-site
USD 155,000 - 185,000
Health benefits
Stock options
Unlimited PTO
+2